I would like to be able to have a predefined variable or constant to run queries with by example
source="syslog" login ip!=OFFICEIPS
where OFFICEIPS is a set of ip's
that way it wont require for us to know all ips every time we do a search but just mantain a table or variable every time a new subnet is added
You can use a lookup and reference them from a file.
Documentation here with an example:
http://docs.splunk.com/Documentation/Splunk/latest/knowledge/Addfieldsfromexternaldatasources
Similar question with details here:
http://splunk-base.splunk.com/answers/38520/how-to-generate-a-report-for-searching-the-request-from-...
You can use a lookup and reference them from a file.
Documentation here with an example:
http://docs.splunk.com/Documentation/Splunk/latest/knowledge/Addfieldsfromexternaldatasources
Similar question with details here:
http://splunk-base.splunk.com/answers/38520/how-to-generate-a-report-for-searching-the-request-from-...
Thx will give it a shot!